Data controller: NNBL Software FZE, licence no. 4431402.01, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Contact: info@heyhey.pl. Full company details and the terms on which the service is provided are available in the Terms of service and the Privacy policy.
Contents
- What the GDPR is
- Roles in heyhey: us, you and your subscribers
- heyhey features that support GDPR compliance
- Data stored in the EU
- Double opt-in
- Easy unsubscribe
- Consent records
- Exporting and deleting data
- Data processing agreement
- Your obligations as the controller of your list
- Users in the United Arab Emirates
- Further information
1. What the GDPR is
The GDPR (General Data Protection Regulation) is a European law that has applied since 25 May 2018. It governs how companies and individuals may process the personal data of people in the European Union.
An email address, a name, an IP address, location data, device identifiers: all of this information is personal data and is subject to the GDPR. If you collect such data, you are a personal data controller and you have specific obligations.
Fines for breaching the GDPR can reach EUR 20 million or 4% of global annual turnover, whichever is higher.
2. Roles in heyhey
In the context of the GDPR, there are three roles in heyhey:
- heyhey, the controller of the data of Users (people who have accounts) and the processor of the data of the subscribers on your lists (acting on your instructions).
- You (the heyhey User), the controller of your subscribers’ data. You are responsible for making sure that the collection and processing of their data complies with the GDPR.
- Your subscribers, the people whose data you process. They have all the rights granted by the GDPR (access, rectification, erasure, etc.).
heyhey provides tools that help you meet your obligations as a controller. However, final responsibility for making sure your activities comply with the GDPR lies with you.
3. heyhey features that support GDPR compliance
By default, heyhey supports the following GDPR requirements:
- Data on servers in the EU (Frankfurt, Germany)
- Encrypted connections (HTTPS/TLS) on every page
- Password encryption in the database (bcrypt)
- Double opt-in (sign-up confirmation) enabled by default
- An automatic “unsubscribe” link in every email sent
- Full consent records: date, IP address, form content
- Export of subscriber data to CSV at any time
- Complete deletion of data within 30 days of a request
- A ready-made privacy policy template for every sign-up page
- A data processing agreement (DPA) available automatically
- A procedure for reporting personal data breaches
- Regular security audits
4. Data stored in the EU
All data of heyhey Users and their subscribers is stored on servers located in Germany (Frankfurt). We do not transfer data outside the European Economic Area (EEA).
We use infrastructure from the following providers:
- Hetzner Online GmbH (Germany), application and database servers
- Cloudflare Inc., CDN and DNS, configured to route traffic to data centres in the EU
- Amazon Web Services (Germany), email sending infrastructure (eu-central-1 region)
- Resend (Germany), transactional email provider (EU region)
5. Double opt-in
Double opt-in is a mechanism that requires a subscriber to take two steps:
- Filling in the sign-up form and entering their email address
- Clicking the confirmation link in the email that is sent to them automatically
The subscriber is added to your list only after they complete the second step. This makes sure that the person really wanted to sign up and owns the email address they entered.
Why it matters: double opt-in is practically the only way to prove that GDPR consent was “informed, unambiguous and given by a clear affirmative action”. If a data protection authority carries out an inspection, you have proof: a log with the date, the IP address and confirmation that the link was clicked.
In heyhey, double opt-in is enabled by default. You can disable it for some lists (e.g. lists imported from another tool where consent has already been collected), but we recommend leaving it on.
6. Easy unsubscribe
Every email sent through heyhey contains an automatic “Unsubscribe” link in the footer. Clicking this link:
- Immediately unsubscribes the subscriber from your list
- Updates their status in the database
- Stops further emails to that address
- Records the date and method of unsubscribing (for the audit log)
You must not remove or modify the unsubscribe link in campaigns. This is a requirement of the GDPR and of our terms of service.
7. Consent records
For each subscriber, heyhey automatically records:
- The date and time of sign-up
- The IP address used to sign up
- The URL of the page where the subscriber signed up
- The content of the form at the time of sign-up (the source of consent)
- The date and time of the double opt-in confirmation (if enabled)
- The IP address of the double opt-in confirmation
- The full history of changes to the subscriber’s status
This information provides full proof of consent in the event of an inspection by a data protection authority or a legal dispute.
8. Exporting and deleting data
8.1. Exporting data
At any time, you can export:
- The full list of subscribers (email, name, custom fields, tags, dates)
- Campaign statistics (opens, clicks, send dates)
- The consent records for each subscriber
Format: CSV, in line with the GDPR data portability requirement.
8.2. Deleting a subscriber
A subscriber can request the deletion of their data at any time. You do this in the heyhey dashboard by clicking “Delete” next to the subscriber. The data is permanently deleted from the database (except for logs needed to prove consent in the event of a dispute, which are kept for 3 years).
8.3. Deleting your account
If you decide to stop using heyhey, you can delete your account in the settings. All data (subscriber list, campaigns, statistics) is deleted within 30 days. The exception is invoice data, which we keep for 5 years (a legal obligation).
9. Data processing agreement
When you use heyhey as a tool to manage your subscriber list, you entrust us with processing your subscribers’ personal data. In this situation, the GDPR requires a data processing agreement (DPA) to be concluded.
The DPA is an integral part of our terms of service and is concluded automatically when you accept the terms of service and create an account. It sets out:
- The scope and purpose of processing subscribers’ data
- The duration of the processing
- The security measures applied by heyhey
- heyhey’s obligations as a processor
- Your rights as a controller
- The procedure for reporting breaches
You can download the full text of the DPA from the “Legal documents” section of your account settings in the heyhey dashboard.
10. Your obligations as the controller of your list
heyhey gives you the tools, but as the controller of your subscriber list, you are responsible for GDPR compliance. In particular:
- Having a privacy policy on the page where you collect email addresses (or using the heyhey template)
- Informing subscribers of the purpose for which you collect their data and how you will use it
- Having a legal basis for processing (most often consent)
- Fulfilling subscribers’ rights: access to their data, rectification, erasure
- Not transferring data outside the EU without appropriate safeguards
- Reporting personal data breaches within 72 hours
- Keeping a record of processing activities (if required given the scale of your business)
If you are unsure about your obligations, consult a lawyer who specialises in the GDPR or a Data Protection Officer (DPO).
11. Users in the United Arab Emirates
For users in the United Arab Emirates, personal data is also handled in line with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data). The tools and safeguards described on this page apply in the same way to all heyhey Users, wherever they are based.
If you have questions about how your data is handled, email us at info@heyhey.pl.
12. Further information
We also recommend reading our other documents:
- Privacy policy, how heyhey processes the data of its Users
- Cookie policy, which cookies the heyhey.ae website uses
- Terms of service, the terms on which the heyhey service is provided
- Acceptable use policy, what you must not do on heyhey
Questions about the GDPR? Email us at info@heyhey.pl.
Official sources of information about the GDPR: